Last updated: August 1, 2026
TrackPitch (“we”, “our”, or “the App”) is a lightweight demo submission tracker for electronic music producers. This Privacy Policy explains what information we collect, how we use it, and how users can control or delete their data.
When you use TrackPitch, we may collect and store the following information:
Account information:
User-provided app data:
Authentication is handled by Supabase. Passwords are submitted directly to Supabase over an encrypted connection and are stored as password verifiers rather than readable plaintext. TrackPitch and Heron&Theodor do not receive or have access to your plaintext password.
We do not intentionally collect sensitive personal information. Users should not enter sensitive personal information into notes or track fields.
We use the information collected through TrackPitch to:
TrackPitch uses Supabase to provide authentication, database storage, cloud sync, and the server function used for account deletion. Your account information and app data are processed in Supabase systems.
TrackPitch is hosted using Netlify. Netlify and related delivery infrastructure may process technical information necessary to deliver the App, such as IP address, request details, device or browser information, and security logs.
TrackPitch uses Cloudflare Turnstile on authentication forms to reduce automated abuse. Cloudflare may process technical and challenge-related information needed to provide that security check.
We do not sell your personal information.
We do not share your TrackPitch data with record labels, artists, advertisers, or other users. Your track and submission data is private to your account unless you choose to share it outside the App.
We may share data only when necessary to:
We use reasonable technical and organizational measures to protect user data. Data transmitted between the App and our service providers is protected using standard encryption in transit where supported.
However, no online service can guarantee complete security.
TrackPitch may provide an export feature that allows users to download their data as a JSON backup file. Users are responsible for storing exported backup files securely.
Users can delete individual records in the App. Users can also permanently delete their account and associated TrackPitch data from Settings, or request deletion through the contact method on the Data Deletion page.
After an in-App account deletion succeeds, the active Supabase Auth account and active database records linked to that account are deleted. Limited technical logs or backup copies controlled by our service providers may remain temporarily under their security and backup-retention processes before scheduled deletion or rotation. Those copies are not available in the active App and are not used to restore an individual deleted account. We may retain limited information only when required for legal compliance, security, fraud prevention, or dispute resolution.
For details, please see our Data Deletion page: https://trackpitch.netlify.app/delete-data.html
TrackPitch is not intended for children under the age of 13. We do not knowingly collect personal information from children.
TrackPitch may be used by users in different countries. By using the App, you understand that your information may be processed in countries where our service providers operate.
We may update this Privacy Policy from time to time. When we make changes, we will update the “Last updated” date above.
If you have questions about this Privacy Policy or want to request data deletion, contact us at:
Heron&Theodor
theodorheron@gmail.com
https://trackpitch.netlify.app